cve/2022/CVE-2022-24990.md
2024-06-18 02:51:15 +02:00

1.9 KiB

CVE-2022-24990

Description

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.

POC

Reference

Github